• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

GeoIP Blocking

pfBlockerNG
4
45
11.0k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ?
    A Former User @A Former User
    last edited by Feb 2, 2021, 10:27 PM

    @antonio-briguglio ops * maxmind

    1 Reply Last reply Reply Quote 0
    • ?
      A Former User @SteveITS
      last edited by Feb 2, 2021, 10:34 PM

      @teamits Hello
      I have activated the maxmin license but I don't know how to configure the geo ip in pfBlockerNG on pfsense 2.4.5 help thanks

      1 Reply Last reply Reply Quote 0
      • ?
        A Former User @SteveITS
        last edited by Feb 2, 2021, 10:37 PM

        @teamits how should i block countries such as the United Kingdom? if you can also help me with screenshots it is easier for me

        S 1 Reply Last reply Feb 2, 2021, 11:11 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @A Former User
          last edited by Feb 2, 2021, 11:11 PM

          What I usually do is set up rules using Alias Native:
          login-to-view
          with all the countries desired. Then set up any firewall rules desired using that alias.

          Note it's usually better to allow the desired countries than block the world, since all the IP addresses of the world would have to be held in memory.

          Also note you have to use the Update tab to generate the files before they can be used.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          ? 3 Replies Last reply Feb 3, 2021, 12:54 AM Reply Quote 0
          • ?
            A Former User @SteveITS
            last edited by Feb 3, 2021, 12:54 AM

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • ?
              A Former User @SteveITS
              last edited by Feb 3, 2021, 12:56 AM

              This post is deleted!
              R 1 Reply Last reply Feb 3, 2021, 1:44 AM Reply Quote 0
              • R
                RonpfS @A Former User
                last edited by RonpfS Feb 3, 2021, 2:05 AM Feb 3, 2021, 1:44 AM

                @antonio-briguglio You are using pfblockerNG, was Format GeoIP available then ? Or maybe it's not be compatible with the new MaxMind requirements? I don't know.

                Maybe it's time to move to pfBlockerNG-devel. Disable pfblockerNG, Uninstall it, install pfblockerNG-devel, insert Maxmind License, configure, Run Force Update, Force Reload All and see if that works.

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                ? S 2 Replies Last reply Feb 3, 2021, 3:25 AM Reply Quote 0
                • ?
                  A Former User @RonpfS
                  last edited by Feb 3, 2021, 3:25 AM

                  @ronpfs It's not like you say. I don't want to uninstall it
                  In my opinion I am wrong or skip a few steps.
                  Help with screenshots

                  R 1 Reply Last reply Feb 3, 2021, 4:44 AM Reply Quote 0
                  • R
                    RonpfS @A Former User
                    last edited by RonpfS Feb 3, 2021, 4:45 AM Feb 3, 2021, 4:44 AM

                    @antonio-briguglio
                    Search the forum: https://forum.netgate.com/search?term=GeoIP&in=titlesposts&matchWords=all&categories[]=62&sortBy=relevance&sortDirection=desc&showAs=posts

                    This one was on first page: https://forum.netgate.com/topic/154140/can-t-get-geoip-to-work/4

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    G 1 Reply Last reply Feb 3, 2021, 1:39 PM Reply Quote 0
                    • G
                      Gertjan @RonpfS
                      last edited by Gertjan Feb 3, 2021, 1:41 PM Feb 3, 2021, 1:39 PM

                      What is the pfBlockerNG version this :

                      login-to-view

                      ?

                      The new GeoIP (they == GeoIP, changed a lot last year) needs to new pfBlockerNG.

                      @antonio-briguglio said in GeoIP Blocking:

                      I don't want to uninstall it

                      You want to use the 'latest and greatest' with the oldest ?

                      login-to-view

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      ? 1 Reply Last reply Feb 20, 2021, 1:16 PM Reply Quote 0
                      • S
                        SteveITS Galactic Empire @RonpfS
                        last edited by Feb 3, 2021, 3:09 PM

                        @ronpfs said in GeoIP Blocking:

                        pfBlockerNG-devel

                        Ah, sorry, I had trouble with pfBlockerNG and the new MaxMind so we switched all our clients to pfBlockerNG-devel. I wasn't even thinking about the package.

                        It kept losing the MaxMind key overnight.
                        https://forum.netgate.com/topic/149343/pfblockerng-maxmind-registration-required-to-continue-to-use-the-geoip-functionality/49

                        The package maintainer has recommended in the forums to use -devel anyway. I am not sure why there are two at this point...? If you uninstall pfBlockerNG and install pfBlockerNG-devel it will import settings.

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote 👍 helpful posts!

                        ? 1 Reply Last reply Feb 3, 2021, 9:05 PM Reply Quote 0
                        • ?
                          A Former User @SteveITS
                          last edited by Feb 3, 2021, 9:05 PM

                          This post is deleted!
                          S 1 Reply Last reply Feb 3, 2021, 9:33 PM Reply Quote 0
                          • S
                            SteveITS Galactic Empire @A Former User
                            last edited by Feb 3, 2021, 9:33 PM

                            The warning is so that you don't run an update while an update is already running. Since your update is 59 minutes away, it's safe to go ahead. Aggiorna I assume is "update" so pick that and click Run.

                            Or wait 59 minutes and it will run an update on its own. :)

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            R ? 2 Replies Last reply Feb 3, 2021, 9:41 PM Reply Quote 0
                            • R
                              RonpfS @SteveITS
                              last edited by RonpfS Feb 3, 2021, 9:42 PM Feb 3, 2021, 9:41 PM

                              @teamits Active pfBlockerNG CRON JOB normally means there is an update running on the box.

                              Inspect pfblockerNG.log file to see what is happening

                              2.4.5-RELEASE-p1 (amd64)
                              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                              ? S 2 Replies Last reply Feb 3, 2021, 9:58 PM Reply Quote 0
                              • ?
                                A Former User @RonpfS
                                last edited by Feb 3, 2021, 9:58 PM

                                @ronpfs yes, but he always does it and doesn't let me update after the time runs out, the stopwatch always starts again
                                and manual updating doesn't

                                R 1 Reply Last reply Feb 3, 2021, 9:59 PM Reply Quote 0
                                • R
                                  RonpfS @A Former User
                                  last edited by Feb 3, 2021, 9:59 PM

                                  @antonio-briguglio What are you seeing in pfblockerng.log?

                                  2.4.5-RELEASE-p1 (amd64)
                                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                  1 Reply Last reply Reply Quote 0
                                  • ?
                                    A Former User @SteveITS
                                    last edited by Feb 3, 2021, 10:11 PM

                                    @teamits how do you put a website blocking warning web page when blocking countries?

                                    R 1 Reply Last reply Feb 3, 2021, 10:13 PM Reply Quote 0
                                    • R
                                      RonpfS @A Former User
                                      last edited by RonpfS Feb 3, 2021, 10:22 PM Feb 3, 2021, 10:13 PM

                                      @antonio-briguglio said in GeoIP Blocking:

                                      @teamits how do you put a website blocking warning web page when blocking countries?

                                      You can't.
                                      You use the Alerts tab to see what is blocked on the IP side.

                                      2.4.5-RELEASE-p1 (amd64)
                                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                      ? 1 Reply Last reply Feb 3, 2021, 10:43 PM Reply Quote 0
                                      • S
                                        SteveITS Galactic Empire @RonpfS
                                        last edited by Feb 3, 2021, 10:19 PM

                                        @ronpfs said in GeoIP Blocking:

                                        Active pfBlockerNG CRON JOB normally means there is an update running on the box

                                        Yeah, missed that giant red label. It's been a long day.

                                        It sounds like pfBlockerNG is set to check for updates every hour? So it should have updated already.

                                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                        Upvote 👍 helpful posts!

                                        1 Reply Last reply Reply Quote 0
                                        • ?
                                          A Former User @RonpfS
                                          last edited by Feb 3, 2021, 10:43 PM

                                          @ronpfs so I want that when a customer for example visits a web page in Turkey that I have blocked that a web page is displayed where it warns that the site is blocked instead of the classic internet page not available

                                          R G 2 Replies Last reply Feb 3, 2021, 10:51 PM Reply Quote 0
                                          16 out of 45
                                          • First post
                                            16/45
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.